The EU KIDS Act Changes the Default: What Europe’s New Child-Safety Proposal Could Mean for Social Media
Europe's proposed EU KIDS Act aims to shift the burden of child safety online, requiring social media platforms to prove their services are age-appropriate by design.

Europe is considering a fundamental change to the way social media treats children: instead of expecting families to prove that a platform is unsafe, platforms could have to show that their services are age-appropriate and safe by design. The proposal is significant — but it is still a proposal, not a rule already in force.
Key takeaways
- On 17 September 2026, the European Commission adopted a proposal for an EU KIDS Act focused on protecting minors from risky digital services and AI systems.
- The proposal would restrict autonomous account creation on certain social networking and video-sharing services for children below 15, while providing a gradual framework around younger users.
- The Commission says the proposal would shift the burden toward service providers to demonstrate that services are age-appropriate and safe by design.
- The KIDS Act is not yet final EU law. Existing rules — including the Digital Services Act and Ireland’s Online Safety Framework — already impose child-safety duties today.
- The direction is increasingly clear: age assurance, private-by-default design, parental tools, safer recommendations and limits on unwanted contact are moving closer to core product infrastructure.
A proposal that changes who has to prove safety
For much of social media’s history, the burden of safety has fallen heavily on users. Parents were expected to understand settings, teenagers were expected to recognise manipulation and harmful contact, and regulators often intervened after harms became visible.
The European Commission’s proposed EU KIDS Act points in another direction. Published on 17 September 2026, the proposal seeks a more harmonised EU framework for protecting minors from risky digital services and AI systems. Its most important idea may not be a single age number. It is the proposed shift in responsibility: services would need to demonstrate that their environments are age-appropriate and safe by design.
That distinction matters. A platform can have hundreds of safety settings and still make unsafe behaviour the easiest path. Safety by design asks a harder question: what happens to a young person by default?
WHAT DOES THE EU KIDS ACT ACTUALLY PROPOSE?
According to the European Commission, the proposal would limit autonomous account creation on certain social networking services and video-sharing platforms for children below the age of 15. The Commission describes this as an EU-wide approach intended to harmonise diverging national rules while maintaining a coherent digital single market.
The proposal also addresses risky digital services and AI systems used by minors. In announcing it, the Commission said service providers would have to show that their services are age-appropriate and safe by design.
That is a major policy direction, but the status must be stated precisely: the KIDS Act is a legislative proposal. It still has to pass through the EU legislative process before becoming final law. Headlines that describe the proposed age framework as already legally binding across Europe would be premature.
WHAT IS ALREADY LAW TODAY?
The proposed KIDS Act sits on top of an existing regulatory foundation rather than starting from zero.
Under the Digital Services Act, online platforms accessible to minors must take appropriate and proportionate measures to ensure a high level of privacy, safety and security for minors. The European Commission’s guidance addresses issues including addictive design, cyberbullying, unwanted contact, recommendation controls and private-by-default accounts.
Ireland also has its Online Safety Framework, overseen by Coimisiún na Meán. The framework includes the Digital Services Act, the Online Safety and Media Regulation Act 2022 — the basis for Ireland’s Online Safety Code — and the EU Terrorist Content Online Regulation.
Ireland has already moved into enforcement. On 8 September 2026, Coimisiún na Meán opened its first formal investigation under the Online Safety Code, examining X’s implementation of age assurance and parental controls. An investigation is not a finding of wrongdoing, but it shows that child-safety requirements are no longer purely theoretical.
Why the age number is only part of the story
Public debate naturally focuses on whether the threshold should be 13, 15, 16 or another age. But a birthday gate alone cannot create an age-appropriate service.
The European Commission has already criticised weak reliance on self-declared birthdays. In April 2026 it preliminarily found Meta in breach of the DSA in relation to risks of children under 13 accessing Instagram and Facebook, noting that a child could enter a false birth date without effective controls checking it. Meta has the right to respond to preliminary findings; they are not a final decision.
At the same time, age assurance creates privacy risks if badly designed. Europe’s age-verification blueprint is intended to let a person prove that they meet an age threshold without revealing their exact age, identity or other unnecessary personal information.
The useful principle is therefore not “collect more ID”. It is: establish the minimum fact required for the safety decision, with the least unnecessary data exposure.
Safety by design means defaults matter
A child-safety regime becomes meaningful when it changes product defaults rather than merely adding another policy page.
The Commission’s existing DSA guidance points toward practical design choices: private-by-default accounts for minors, stronger controls over recommendations, tools to block users, limits on unwanted downloads and contact, and measures designed to reduce compulsive use.
The G7’s common principles on protecting minors online, agreed in May 2026, reinforce the same direction. They call for safety-by-design risk management, meaningful transparency and robust, reliable, privacy-preserving age assurance.
This matters because product architecture shapes behaviour. A safety setting that exists but is buried five menus deep is not equivalent to a safe default. A reporting button that is technically present but difficult to understand is not equivalent to an effective reporting system.
What this could mean for families in ireland
For Irish families, the immediate message is not that a new EU age ban suddenly applies today. It does not. The KIDS Act is proposed legislation.
The more useful takeaway is that Europe is converging around a model in which platforms carry more responsibility for the environments they create for children. Parents should still review account privacy, content controls and contact settings, but regulation is increasingly challenging the assumption that families alone should compensate for risky platform design.
Families can also ask better questions. Is a teenager’s account private by default? Can unknown adults contact them? Can sensitive content be recommended automatically? Are reporting and blocking tools obvious? Does the platform know the user is a minor, and if so, what changes because of that fact?
Those questions are more revealing than whether a service merely says it is suitable for teenagers.
Where safegram fits — live, developing and planned
Safegram’s product direction is built around reducing anonymous trust gaps and treating younger users as a distinct safety group. It is important, however, to distinguish what is available now from what remains under development.
LIVE: Safegram is available on iOS and Android. Verification for users, creators and businesses, social profiles and Safegram Exchange are part of the live product. Businesses and creators must be verified before adding products or services to Exchange.
DEVELOPING / BETA: Safegram continues to develop and test marketplace, booking, discovery, messaging and AI-assisted experiences. Individual flows can change during testing and rollout.
PLANNED / EXPANDING: Safegram’s roadmap includes stronger teen/family protections, age-aware discovery and contact boundaries, family notifications and additional automated safety signals. These features should not be treated as universally deployed until Safegram marks them live.
The intended design principle is separation without surveillance: reducing inappropriate contact and exposure for younger users without assuming that family safety requires parents to read private conversations. That direction is consistent with the broader European move toward age-appropriate, privacy-conscious product design, but Safegram’s planned features should be judged on their implementation once deployed.
The bigger change: child safety is becoming a product requirement
The proposed KIDS Act is important partly because of what it says about the next phase of technology regulation. Europe is moving beyond asking whether platforms have moderation teams. It is increasingly asking whether the underlying product was designed to reduce foreseeable risk.
That shift affects recommender systems, account defaults, age assurance, contact permissions, advertising, AI interactions and parental controls. It also creates legitimate questions about privacy, proportionality, technical accuracy and freedom of expression.
Those debates will continue through the legislative process. But the direction is difficult to miss: when a service is built for or accessible to children, “we gave users a settings menu” is becoming a weaker answer to the question of safety.
Frequently asked questions
Is the EU KIDS Act already law?
No. The European Commission adopted the proposal on 17 September 2026. It must go through the EU legislative process before it can become final law.
Does the proposal ban all social media for everyone under 15?
No. The Commission describes a framework limiting autonomous account creation on certain social networking and video-sharing services below age 15. The final legal text may change during negotiations, so it should not be described as a blanket rule already in force.
What rules protect children online in the EU today?
The Digital Services Act already requires platforms accessible to minors to take appropriate and proportionate measures to protect minors’ privacy, safety and security. Ireland also applies its Online Safety Framework and Online Safety Code within their respective scopes.
Why isn’t a self-declared birthday enough?
For higher-risk services it can be easy to circumvent. European regulators are increasingly focused on effective, proportionate age-assurance methods rather than relying solely on a date typed into a form.
Does age assurance require giving every platform a passport?
No. The EU’s privacy-preserving age-verification approach is designed to prove an age threshold without disclosing exact age, identity or other unnecessary details.
What does “safe by design” mean?
It means considering safety in the architecture and defaults of a service — for example account privacy, contact permissions, recommendations and reporting — rather than relying only on users to find and configure safety settings later.
Are Safegram’s teen/family protections all live?
No. Safegram has live verification and core platform functionality, while additional teen/family protections and age-aware safety mechanisms are developing or planned. Their status should be described according to actual rollout.
Can regulation make social media completely safe for children?
No. Regulation can change incentives and minimum standards, but child safety also depends on effective implementation, education, family support, enforcement, privacy protections and ongoing product design.
Source references
-
European Commission, “EU KIDS Act to restrict social media platforms’ access to children in the EU”, 17 September 2026 (page updated 30 September 2026).
-
European Commission, “Proposal for EU KIDS Act — EU Keeping Internet Digital Spaces Accountable and Trustworthy”, 17 September 2026.
-
European Commission, “The impact of the Digital Services Act on digital platforms — Protection for minors”, accessed 2 October 2026.
-
Coimisiún na Meán, “Investigation commenced into X under Online Safety Code”, 8 September 2026.
-
Coimisiún na Meán, “Online Safety Framework”, accessed 2 October 2026.
-
European Commission, “Commission preliminarily finds Meta in breach of Digital Services Act for failing to prevent minors under 13 from using Instagram and Facebook”, 29 April 2026.
-
European Commission, “Commission urges Member States to rollout EU age verification app”, 29 April 2026.
-
European Commission, “Commission welcomes G7 agreement on common principles for protecting minors online”, 29 May 2026.
More from Safegram
Try Safegram
Privacy-first social and a verified marketplace, built in Dublin.